Dive Brief:
- Almost three-quarters of facilities have the kind of building automation system that has been targeted in ransomware attacks, an analysis by cybersecurity company Armis Labs says.
- The high percentage stems in part from the legacy BACnet standard that most building systems use, the company says. The standard was introduced in the 1990s without security protocols because the systems at the time weren’t network connected.
- The open communication standard is now an organizational vulnerability that bad actors can exploit, the company says. It pointed to a hack in August of Shared Health, the largest hospital in Manitoba, Canada, in which hackers seized control of the facility’s elevators, HVAC monitoring system and security office, affecting its ability to issue access badges. “Attackers have worked out that they do not need to encrypt data” for ransom, the company says, “when they can seize badges, pressure the building relationships that clinical work depends on, and put operating-room climate on the table.”
Dive Insight:
There isn’t widespread targeting of building systems, but as hackers become more familiar with their vulnerabilities, facility managers can expect to see them increase, Troy Cruzen, virtual chief information security officer at Fortified Health Security, told Facilities Dive last year.
These systems “were just designed to provide HVAC capabilities,” said Cruzen, whose company specializes in hardening healthcare facility systems. “That’s just the reality of hackers. They can leverage those vulnerabilities and make it a bigger deal than they were designed to be.”
The use of AI is accelerating hackers’ learning curve, says the analysis from Armis, which workflow automation company ServiceNow acquired earlier this year.
“AI-accelerated vulnerability research is shortening the time between a flaw being found and weaponized,” Armis says.
Meanwhile, patching vulnerabilities remains slow because of the role of HVAC and other systems in building operations. “Critical infrastructure cannot simply be taken offline,” the company says. “The remediation backlog grows faster than teams can clear it.”
Armis says 73% of organizations have at least one known exploited vulnerability in their building systems, and that exposure is likely to grow because 91% of the systems organizations are using communicate over insecure protocols, including BACnet. Other legacy protocols are KNX, which is used mainly in Europe, and Modbus.
Hackers exploited KNX vulnerabilities in 2021 when they locked out office operators in Germany from their building systems. The hack left most of the building devices inaccessible, affecting lighting, motion detectors and shutter controllers. “The attackers turned the system’s own security feature against it, wiping devices and locking them,” Armis says.
HVAC systems, chilled water plants, fire and life safety devices and elevators, among other systems today, are designed to be integrated into the organization’s network, but the systems generally remain built on vulnerable protocols, Armis says.
The “installed base” of the systems “carries decades of insecure-by-design technology now exposed to a faster, more automated threat landscape,” the company says.
The company calls for organizations to treat the security of building automation systems as a business continuity problem, not a technology problem, and concentrate security responsibility into one hand, rather than having facilities manage security of building systems while IT manages security of information systems.
“The organizations handling this well … classified building automation as a business continuity system, gave it a named owner instead of leaving it between facilities, IT, and the integrator, and held it to the same standard as the clinical, trading, or production systems it quietly keeps running,” Armis says. “The goal is not a perfect posture. It is a shrinking attack surface and uninterrupted uptime.”